pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can set item_number, cart_order_id, or the PayPal custom field while paying a token amount, or submit uncompleted PayPal IPN payments, to gain the most expensive membership and its paid features.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ph7software
Ph7software ph7builder |
|
| Vendors & Products |
Ph7software
Ph7software ph7builder |
Thu, 08 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pH7Builder (pH7 Social Dating CMS) before 18.5.1 contains a payment validation vulnerability that allows registered low-privileged members to obtain any membership tier by supplying client-controlled plan and amount fields. Attackers can set item_number, cart_order_id, or the PayPal custom field while paying a token amount, or submit uncompleted PayPal IPN payments, to gain the most expensive membership and its paid features. | |
| Title | pH7Builder before 18.5.1 Payment Bypass via Payment Module MainController | |
| Weaknesses | CWE-472 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T17:52:19.191Z
Reserved: 2026-10-08T14:05:59.689Z
Link: CVE-2026-107636
No data.
Status : Deferred
Published: 2026-10-08T15:17:46.543
Modified: 2026-10-08T18:17:25.180
Link: CVE-2026-107636
No data.
OpenCVE Enrichment
Updated: 2026-10-08T16:30:04Z
Weaknesses